SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefMonday, September 07, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Active Unauthenticated SSH Hijacking of MikroTik Routers | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 5 ARTICLES |
|
■ ANALYST TLDR Active exploitation of a critical unauthenticated SSH bypass vulnerability in MikroTik RouterOS is allowing attackers to hijack internet-exposed routers and establish administrative persistence. Concurrently, threat actors are leveraging invisible Unicode characters for ASCII smuggling to evade email security filters, while new REVSTEALER-linked modules are actively disabling Windows Defender and Windows Update to deploy cryptocurrency miners. |
|
■ CRITICAL STORIES Critical MikroTik Vulnerability Exploited in the Wild Attackers are bypassing authentication on internet-exposed MikroTik SSH services to gain full administrative control and create persistent rogue accounts, requiring immediate patching and compromise assessment. |
Four REVSTEALER-Linked Modules Disable Windows Update and Defender Newly documented post-compromise modules associated with the REVSTEALER information stealer persist on infected systems to disable critical security controls and run cryptocurrency miners. |
Attackers Conceal Phishing Lures Using Invisible Unicode Characters Threat actors are utilizing ASCII smuggling techniques with invisible Unicode characters to bypass email security gateways and deliver malicious payloads undetected. |
|
■ CVEs IDENTIFIED [CVE-TBD] MikroTik RouterOS — Unauthenticated SSH authentication bypass leading to full administrative takeover |
|
■ THREAT ACTORS REVSTEALER Operators | Cybercrime / Financial |
Deploying persistent modules to disable Windows Defender/Update and run crypto miners |
Unknown Threat Actors | Cybercrime |
Exploiting unauthenticated SSH vulnerability in MikroTik routers to add rogue administrative accounts |
Phishing Actors | Cybercrime |
Utilizing invisible Unicode characters (ASCII smuggling) to evade email security filters |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Attackers exploiting internet-exposed MikroTik SSH services. |
| T1556 | | Modify Authentication Process | Attackers bypassing SSH authentication on MikroTik routers. |
| T1136.001 | | Create Account: Local Account | Attackers adding new administrative accounts to hijacked MikroTik routers. |
| T1027.007 | | Obfuscated Files or Information: Stripped Payloads / ASCII Smuggling | Threat actors using invisible Unicode characters to evade email security filters. |
| T1562.001 | | Impair Defenses: Disable or Modify Tools | REVSTEALER modules disabling Windows Defender. |
| T1562.004 | | Impair Defenses: Disable or Modify System Firewall / Updates | REVSTEALER modules disabling Windows Update. |
|
■ PATCH PRIORITY MikroTik RouterOS — Unauthenticated SSH authentication bypass allowing full administrative control and active exploitation — SANS / CERT Polska |
Microsoft Windows — REVSTEALER modules disabling Windows Defender and Windows Update to run crypto miners — Elastic Security Labs |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately apply the latest MikroTik RouterOS patch to resolve the unauthenticated SSH bypass vulnerability ([CVE-TBD]). |
| 2 | [P1] Audit all MikroTik RouterOS user accounts for unauthorized administrative accounts and restrict SSH access to trusted source IPs only. |
| 3 | [P2] Update Windows Defender signatures and monitor for unauthorized registry modifications or services attempting to disable Windows Defender or Windows Update (associated with REVSTEALER). |
| 4 | [P2] Update email security gateway rules to detect and block emails containing invisible Unicode characters used for ASCII smuggling. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |